RHSA-2020:4220HighCVSS 7.7

Red Hat Security Advisory: OpenShift Container Platform 4.4.27 openshift-jenkins-2-container security update

Published
October 13, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2019-17638 — jetty: double release of resource can lead to information disclosure CVE-2020-2229 — jenkins: user-specified tooltip values leads to stored cross-site scripting CVE-2020-2230 — jenkins: stored XSS vulnerability in project naming strategy CVE-2020-2231 — jenkins: stored XSS vulnerability in 'trigger builds remotely'

🎯 Affected products4

  • Red Hat OpenShift Container Platform 4.4
  • openshift4/ose-jenkins@sha256:4edf1e303f9883b2de2a6717582368da4f802f082ea239c2e3cf9c933a075451_ppc64le as a component of Red Hat OpenShift Container Platform 4.4
  • openshift4/ose-jenkins@sha256:c3a594503102efc385f273f3fcd4fc4108c4fe2a9a86eb3b96946f54c54f2a05_amd64 as a component of Red Hat OpenShift Container Platform 4.4
  • openshift4/ose-jenkins@sha256:ebd9fc4b31ba647ed771650254c47ba48a3acde2dd98fced23ca0d4c942050e6_s390x as a component of Red Hat OpenShift Container Platform 4.4

✅ Remediation

For OpenShift Container Platform 4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.4/release_notes/ocp-4-4-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.4/updating/updating-cluster-cli.html.

🔗 References (7)